WP Force Lowercase URLs Security & Risk Analysis

wordpress.org/plugins/wp-force-lowercase-urls

Perform a 301 redirect from an uppercase URL to the lowercase version for all non-admin URLs

7K active installs v2.0.1 PHP + WP 3.4+ Updated Feb 3, 2019
301lowercaseredirecturl
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Force Lowercase URLs Safe to Use in 2026?

Generally Safe

Score 85/100

WP Force Lowercase URLs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'wp-force-lowercase-urls' plugin v2.0.1 exhibits an exceptionally strong security posture based on the provided static analysis data. The plugin demonstrates excellent adherence to secure coding practices, with no identified dangerous functions, all SQL queries utilizing prepared statements, and all output being properly escaped. Furthermore, the absence of file operations, external HTTP requests, and any form of taint flow analysis reporting critical or high severity issues indicates a clean codebase. The lack of any recorded vulnerabilities, past or present, further solidifies this positive assessment.

While the plugin's attack surface is effectively zero and its code signals are all positive, the absence of nonce checks and capability checks on the zero AJAX handlers and zero REST API routes is a minor observation. Given the plugin's stated purpose and the lack of any interaction points, this is unlikely to be a practical concern. The plugin's strengths lie in its minimal code footprint, focus on secure SQL and output handling, and its spotless vulnerability history, suggesting a well-maintained and secure component. The primary weakness, if any can be construed, is the sheer lack of security mechanisms being necessary due to the absence of any user-facing or administrative functionality that would typically require such checks.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

WP Force Lowercase URLs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Force Lowercase URLs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP Force Lowercase URLs Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitwp-force-lowercase-urls.php:26
Maintenance & Trust

WP Force Lowercase URLs Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedFeb 3, 2019
PHP min version
Downloads27K

Community Trust

Rating100/100
Number of ratings5
Active installs7K
Developer Profile

WP Force Lowercase URLs Developer Profile

joshbuchea

1 plugin · 7K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Force Lowercase URLs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
wp-force-lowercase-urls/wp-force-lowercase-urls.php?ver=2.0.1

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP Force Lowercase URLs